summaryrefslogtreecommitdiff
path: root/app/models/asset.rb
diff options
context:
space:
mode:
authorerdgeist <erdgeist@erdgeist.org>2026-07-31 18:14:30 +0200
committererdgeist <erdgeist@erdgeist.org>2026-07-31 18:14:30 +0200
commit464af1625349d557f688da9f845471ef8b80a5f9 (patch)
treeaab415abf115f20ccbcdfad49c27ce5d1bd61134 /app/models/asset.rb
parent8c6a6516e1dc5c1b4f12740a6f7b32765b530bb7 (diff)
Gate live-content changes on restricted surfaces
publish_draft!, trash!, destroy_from_trash!, attach_asset! and Asset#destroy_witnessed! now refuse unless the acting user holds redaktion, and only when the subject is on a restricted surface: the front page, the updates tree that feeds ~100k subscribers, or disclosure. Drafting, autosaving, tagging and creating stay free everywhere for everyone. Enforcement is in the models rather than the controllers, since attach_asset! and the rest are reachable from rake tasks and internal paths. It follows the errors.add-plus-bare-raise pattern the rest of Node already uses, so every existing RecordInvalid rescue reports it with a localised message; only assets_controller#destroy needed a rescue added. A nil user is treated as a system context and bypasses the gate. The default nil on three of those verbs is what makes that reachable, and removing those defaults once every call site passes a user is the next tightening.
Diffstat (limited to 'app/models/asset.rb')
-rw-r--r--app/models/asset.rb12
1 files changed, 12 insertions, 0 deletions
diff --git a/app/models/asset.rb b/app/models/asset.rb
index 8cec4371..b256b929 100644
--- a/app/models/asset.rb
+++ b/app/models/asset.rb
@@ -41,6 +41,13 @@ class Asset < ApplicationRecord
41 :ids => page_ids).distinct 41 :ids => page_ids).distinct
42 end 42 end
43 43
44 # An asset's reach is the reach of the pages carrying it: destroying one
45 # removes it from every live page at once, so a single restricted
46 # attachment makes the destruction a restricted act.
47 def restricted?
48 attached_nodes.any?(&:restricted?)
49 end
50
44 # Witnessed destruction. Destroying an asset is a public-facing act 51 # Witnessed destruction. Destroying an asset is a public-facing act
45 # even when unattached. The original and its variants are publicly 52 # even when unattached. The original and its variants are publicly
46 # reachable under /system/uploads, so an entry is always written, 53 # reachable under /system/uploads, so an entry is always written,
@@ -49,6 +56,11 @@ class Asset < ApplicationRecord
49 # participates as the first non-Node subject (its participant row 56 # participates as the first non-Node subject (its participant row
50 # dangles after destroy, by design, the name lives on in metadata). 57 # dangles after destroy, by design, the name lives on in metadata).
51 def destroy_witnessed! user: 58 def destroy_witnessed! user:
59 if user && !user.may_change_live?(self)
60 errors.add(:base, :not_permitted)
61 raise ActiveRecord::RecordInvalid.new(self)
62 end
63
52 ActiveRecord::Base.transaction do 64 ActiveRecord::Base.transaction do
53 affected = attached_nodes.to_a 65 affected = attached_nodes.to_a
54 headline_losses = affected.select do |node| 66 headline_losses = affected.select do |node|